Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC
PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP
CVE-2020-3153MEDIUMbajo ataqueransomware15 may 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RIESGO
abrir
GitHub PoC
CVE-2018-10933_Scanner
CVE-2018-10933CRITICAL15 may 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC31
CVE-2020-10199 回显版本
CVE-2020-10199HIGHbajo ataque15 may 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
GitHub PoC
cdedmondson/Modified-CVE-2015-3306-Exploit
CVE-2015-330615 may 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC
ES File Explorer Open Port Vulnerability - CVE-2019-6447
CVE-2019-644714 may 2020
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RIESGO
abrir
GitHub PoC15
Proof of concept for Weblogic CVE-2020-2883
CVE-2020-2883CRITICALbajo ataque13 may 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
GitHub PoC
teddy47/CVE-2019-13272---Documentation
CVE-2019-13272HIGHbajo ataque13 may 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC1
CVE-2004-1769 // Mass cPanel Reset password
CVE-2004-176913 may 2020
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x,
35RIESGO
abrir
GitHub PoC
Microsoft Windows - 'afd.sys' Local Kernel Privilege Escalation Exploit Report (CVE-2011-1249)
CVE-2011-124913 may 2020
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RIESGO
abrir
GitHub PoC
CVE-2018-20250漏洞利用
CVE-2018-20250HIGHbajo ataqueransomware13 may 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC
This is a Dirty Cow (CVE-2016-5195) privilege escalation vulnerability exploit
CVE-2016-5195HIGHbajo ataque12 may 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Dilith006/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque12 may 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
dinidhu96/IT19013756_-CVE-2016-4971-
CVE-2016-497112 may 2020
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RIESGO
abrir
GitHub PoC
SachinThanushka/CVE-2018-1160
CVE-2018-1160CRITICAL12 may 2020
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RIESGO
abrir
GitHub PoC
Dirtycow also is known as CVE-2016-5195
CVE-2016-5195HIGHbajo ataque12 may 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Dilan-Diaz/Point-to-Point-Protocol-Daemon-RCE-Vulnerability-CVE-2020-8597-
CVE-2020-8597CRITICAL12 may 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RIESGO
abrir
GitHub PoC
This is a brief exploitation of CVE-2019-14287 Sudo Security Bypass Vulnerability.
CVE-2019-1428712 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
SNP Assignment on a Linux vulnerability
CVE-2019-10149CRITICALbajo ataque12 may 2020
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC3
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153812 may 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC
CVE-2019-5736
CVE-2019-573612 may 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC
This is an individual assignment for secure network programming
CVE-2014-6271CRITICALbajo ataque12 may 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
alokaranasinghe/cve-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware12 may 2020
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC4
CVE-2019-6111 vulnerability exploitation
CVE-2019-6111MEDIUM12 may 2020
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RIESGO
abrir
GitHub PoC
This document explain Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [CVE-2019-19781]
CVE-2019-19781CRITICALbajo ataqueransomware12 may 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC
sachinthaBS/Spectre-Vulnerability-CVE-2017-5753-
CVE-2017-5753MEDIUM12 may 2020
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC1
BimsaraMalinda/Linux-Kernel-4.4.0-Ubuntu---DCCP-Double-Free-Privilege-Escalation-CVE-2017-6074
CVE-2017-607412 may 2020
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RIESGO
abrir
GitHub PoC
SMBGhost CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware12 may 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
DewmiApsara/CVE-2019-14287
CVE-2019-1428712 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
janod313/-CVE-2019-14287-SUDO-bypass-vulnerability
CVE-2019-1428712 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
This is the exploitation of sudo security bypass vulnerability
CVE-2019-1428712 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
anteriorpágina 398 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.